First published: Thu Jun 14 2007(Updated: )
Unspecified vulnerability in sources/action_public/xmlout.php in Invision Power Board (IPB or IP.Board) 2.2.0 through 2.2.2 allows remote attackers to modify another user's profile data, such as an AIM screen name or Yahoo! identity.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invision Power Board | =2.2 | |
Invision Power Board | =2.2.1 | |
Invision Power Board | =2.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3219 is considered a moderate severity vulnerability allowing unauthorized profile data modification.
To fix CVE-2007-3219, upgrade Invision Power Board to version 2.2.3 or later where the vulnerability has been addressed.
CVE-2007-3219 affects Invision Power Board versions 2.2.0 through 2.2.2.
Yes, CVE-2007-3219 can be exploited remotely by attackers to modify user profile data.
CVE-2007-3219 allows the modification of sensitive user profile data, including AIM screen names and Yahoo! identities.